
A critical zero-day vulnerability in Fortinet FortiMail is being actively exploited in the wild, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog.
Tracked as CVE-2026-104286 and rated 9.8 (Critical) on the CVSS scale, the vulnerability allows unauthenticated attackers to write arbitrary files to the underlying system through crafted HTTP or HTTPS requests.
Fortinet disclosed the vulnerability on October 1 and confirmed that it has been exploited in the wild. The company has not disclosed how many FortiMail appliances have been compromised, when the attacks began, or who is behind the activity.
The flaw is caused by a path traversal vulnerability combined with improper handling of NULL bytes. An attacker can exploit the issue without authentication, potentially allowing them to modify files on an affected FortiMail appliance.
FortiMail is Fortinet’s email security gateway designed to protect organizations against spam, malware, phishing, and other email-based threats. Because the vulnerable functionality is exposed through the product's web interface, internet-accessible management interfaces are a particular concern.
FortiMail versions affected
CVE-2026-104286 affects several supported FortiMail branches:
- FortiMail 8.0.0 through 8.0.1
- FortiMail 7.6.0 through 7.6.6
- FortiMail 7.4.0 through 7.4.8
- FortiMail 7.2.0 through 7.2.9
Fortinet said fixes are being prepared in FortiMail 8.0.2, 7.6.7, and 7.4.9. Users of the 7.2 branch are advised to move to the 7.4 branch or later.
Until the updates are available, Fortinet recommends disabling Identity-Based Encryption (IBE) support or restricting access to the FortiMail management interface from the internet.
The company also recommends limiting management access to trusted private networks where possible.
Fortinet shares compromise indicators
Fortinet has published indicators of compromise that organizations can use to determine whether their FortiMail appliances may have been targeted.
The indicators include the following IP addresses:
- 79.141.169[.]187
- 45.129.0[.]192
Fortinet also identified several files that were added or modified on compromised systems, including:
/data/lib/liblog.so/data/bin/webconsole/data/bin/mailservice/data/etc/ld.so.preload/bin/smit/data/etc/httpd.conf/data/migadmin.tar.gz
The company has not attributed the attacks to a specific threat actor or disclosed the number of affected customers.
CISA sets October 4 deadline
CISA added CVE-2026-104286 to its KEV catalog on October 1, citing evidence that the vulnerability is being actively exploited.
Federal Civilian Executive Branch agencies have until October 4 to apply the available mitigations or fixes. CISA's KEV deadlines are mandatory for covered federal agencies, while the agency also encourages other organizations to prioritize vulnerabilities listed in the catalog.
The short remediation window reflects the risk posed by an actively exploited vulnerability that does not require authentication. Organizations using affected FortiMail versions should review internet exposure, apply Fortinet's available workarounds, and check the published indicators for signs of compromise while waiting for the appropriate security updates.







Leave a Reply